Change /logout from GET to POST (#515)

This commit is contained in:
calzoneman 2015-10-26 23:21:09 -07:00
parent 50ca141f1d
commit 26e8660af4
3 changed files with 16 additions and 4 deletions

View file

@ -67,8 +67,10 @@ mixin navloginform(redirect)
mixin navlogoutform(redirect)
p#logoutform.navbar-text.pull-right
form#logoutform.navbar-text.pull-right(action="/logout", method="post")
input(type="hidden", name="dest", value=baseUrl + redirect)
input(type="hidden", name="_csrf", value=csrfToken)
span#welcome Welcome, #{loginName}
span  · 
a#logout.navbar-link(href="/logout?dest=#{encodeURIComponent(baseUrl + redirect)}&_csrf=#{csrfToken}") Logout
input#logout.navbar-link(type="submit", value="Logout")